FREE CSCRF GAP ASSESSMENT

SEBI CSCRF Gap Assessment

Find out where your firm stands against SEBI's Cybersecurity and Cyber Resilience Framework in 5 minutes. Built for brokers, AMCs, advisers, and market intermediaries.

What You'll Discover

A CSCRF-specific readiness snapshot for your RE category

Readiness by CSCRF Domain

See where you stand across Governance, Identify, Protect, Detect, Respond, and Recover.

Category-Appropriate Scoping

Obligations differ for MIIs, Qualified, Mid-size, Small-size, and Self-certification REs — assess against the right bar.

SOC, VAPT & Audit Gaps

Identify missing SOC coverage, overdue VAPT cycles, and cyber audit preparation gaps.

Incident Reporting Readiness

Check whether you can realistically meet the 6-hour CERT-In reporting requirement.

Prioritized Remediation Plan

Get gaps ranked critical, high, and medium with suggested timeframes.

CCI Preparation

Understand what feeds your Cyber Capability Index before you have to report it.

Start Your CSCRF Assessment

Select Your RE Category

Current State Assessment

Do you have a board-approved cybersecurity and cyber resilience policy?
Governance
Have you designated a CISO or officer responsible for cybersecurity?
Governance
Do you have SOC coverage (own SOC, group SOC, or Market SOC subscription)?
Security Operations
Do you conduct periodic VAPT on critical systems and track findings to closure?
Security Testing
Is MFA enforced for all users, with privileged access management in place?
Access Control
Is sensitive data (client KYC, holdings, credentials) classified and encrypted at rest and in transit?
Data Protection
Are logs collected centrally and retained for the required period?
Monitoring & Logging
Can you report cybersecurity incidents to CERT-In within 6 hours of detection?
Incident Response
Do you maintain an SBOM for critical applications and assess vendor cyber risk?
Third-Party Risk
Do you calculate and report your Cyber Capability Index (if applicable to your category)?
Cyber Capability Index
Have you undergone a cyber audit by a CERT-In empanelled auditor?
Cyber Audit
Do all employees receive cybersecurity awareness training, including phishing simulations?
Awareness & Training

No credit card required • Results in 60 seconds

Continue Your CSCRF Journey

Resources for SEBI-regulated entities

Turn Your Gaps Into an Audit-Ready Program

LowerPlane automates CSCRF evidence collection, control testing, and audit preparation for brokers, AMCs, advisers, and intermediaries